Privacy Policy
Last updated: March 24, 2026
BuildDream ("we," "us," or "our") provides an AI-powered art education platform designed for use in K-12 classrooms. We are committed to protecting the privacy of all users, especially children. This Privacy Policy explains how we collect, use, store, and protect information in compliance with the Children's Online Privacy Protection Act (COPPA), the Family Educational Rights and Privacy Act (FERPA), and applicable state privacy laws.
1. Information We Collect
1.1 Teacher Accounts (Adults)
When teachers register, we collect:
- Email address and display name (via Clerk authentication)
- Credit balance and usage history
- Uploaded images and generated artworks
- Classroom names and session history
1.2 Student Users (Children Under 13)
We do not collect any personally identifiable information (PII) from students. Specifically:
- No account creation required — students do not register, provide emails, or create passwords
- No names collected — students are identified only by a number or alias chosen by their teacher (e.g., "05" or "Student A")
- No device identifiers — we do not collect IP addresses, device IDs, or browser fingerprints from student sessions
- No tracking or analytics — we do not use cookies, pixels, or tracking technologies on student-facing pages
- No behavioral profiling — we do not build profiles of student behavior or preferences
1.3 Student-Created Content
Students upload drawings and receive AI-generated artwork. These images are stored temporarily and are associated with a classroom session, not with any personal identifier. Images are automatically deleted after the retention period described in Section 6.
2. How We Use Information
- To provide the AI art generation service
- To manage classroom sessions and display student work to their teacher
- To manage teacher credits
- To maintain and improve the security of our platform
We do not use student data for advertising, marketing, or any purpose unrelated to the educational service.
3. COPPA Compliance
BuildDream is designed to comply with the Children's Online Privacy Protection Act (COPPA), including the updated rules effective April 22, 2026.
- School Consent Exception: When BuildDream is used in a school setting, the school (through the teacher) provides consent on behalf of parents for the limited collection of student-created content, solely for educational purposes. This consent is governed by the school's relationship with parents under FERPA.
- No PII Collection: Since we do not collect names, email addresses, or any other personal identifiers from students, the scope of COPPA's requirements is significantly reduced.
- Parental Rights: Parents may contact us at any time to review, delete, or refuse further collection of their child's information by emailing privacy@builddream.art.
- Data Minimization: We collect only what is strictly necessary to provide the educational service.
4. FERPA Compliance
When used in schools, student artwork may constitute "education records" under FERPA. We comply with FERPA as follows:
- We act as a "school official" with a "legitimate educational interest" under the school's direction
- Student data is used solely for the educational purpose authorized by the school
- We do not share student data with any third parties except as necessary to provide the service (see Section 5)
- We do not sell, rent, or trade student information under any circumstances
- We are prepared to enter into Data Processing Agreements (DPAs) with school districts upon request
5. Third-Party Services
We use the following third-party services to operate BuildDream:
Google AI (Gemini API)
Student drawings are sent to Google's Gemini API for AI processing. Google processes this data under their Data Processing Addendum. Google does not use API inputs to train their models. Images are processed transiently and not retained by Google after processing.
Supabase (Database & Storage)
Data is stored on Supabase infrastructure (AWS). All data is encrypted at rest and in transit. Supabase is SOC 2 Type II certified.
Clerk (Teacher Authentication Only)
Used only for teacher account authentication. Student sessions do not interact with Clerk in any way.
We do not use any advertising networks, analytics trackers, or social media plugins on student-facing pages.
6. Data Retention & Deletion
6.1 Student Data
- Student-uploaded images and generated artworks are retained while the classroom exists
- When a teacher deletes a classroom, all associated student data (uploads, artworks, session tokens, student numbers) is permanently deleted
- Teachers may download and export student work at any time
- Parents or schools may request immediate deletion by contacting us
6.2 Teacher Data
- Teacher accounts and data are retained as long as the account is active
- Upon account deletion, all associated data (classrooms, works, uploads) is permanently removed within 30 days
6.3 Deletion Requests
Teachers, schools, or parents may request immediate deletion of any data by contacting privacy@builddream.art. We will process deletion requests within 5 business days.
7. Data Security
- All data is encrypted in transit (TLS 1.2+) and at rest (AES-256)
- Database access is restricted through Row-Level Security policies
- Student-facing pages require no authentication cookies or persistent identifiers
- API endpoints are rate-limited to prevent abuse
- Security headers (X-Frame-Options, X-Content-Type-Options, Referrer-Policy) are enforced
- Admin operations are logged with audit trails
8. Content Safety
All AI-generated content is filtered through safety rules designed for children:
- AI prompts explicitly prohibit violence, nudity, weapons, and inappropriate content
- Generated images are safe for all ages
- Teachers control which art styles are available to students
- Uploaded images are validated for file type and size
9. School District Agreements
We offer Data Processing Agreements (DPAs) for school districts. Our DPA template addresses:
- FERPA and COPPA compliance obligations
- Data ownership (the school retains ownership of all student-created content)
- Data breach notification procedures (within 72 hours)
- Data deletion upon contract termination
- Restrictions on data use (educational purposes only)
- Sub-processor disclosures
To request a DPA, contact schools@builddream.art.
10. Your Rights
Teachers, parents, and schools have the right to:
- Access all data we hold about them or their students
- Request correction of inaccurate data
- Request deletion of all data
- Export data in a portable format
- Withdraw consent at any time
- File a complaint with the FTC (for COPPA) or the Department of Education (for FERPA)
11. California Residents
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Age-Appropriate Design Code Act (CAADCA). We do not sell personal information. For California-specific requests, contact privacy@builddream.art.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated to registered teachers via email and posted on this page. Continued use after changes constitutes acceptance. The "Last updated" date at the top of this page indicates when this policy was last revised.
13. Contact Us
For privacy-related questions, data requests, or DPA inquiries:
Email: privacy@builddream.art
School District Inquiries: schools@builddream.art